CVE-2026-3219 pip Flaw: Ambiguous ZIP/Tar Parsing Enables Supply-Chain Attacks on Windows Developers
The Python Package Authority (PyPA) disclosed CVE-2026-3219 on April 20, 2026, a medium-severity flaw in pip that opens a new vector for supply-chain attacks. The vulnerability allows a specially...